Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

431 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.1)1.1%—Jenkins Amazon EC215/1/202017/6/2026
A missing permission check in Jenkins Amazon EC2 Plugin 1.47 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL within the AWS region using attacker-specified credentials IDs obtained through another method.
ModificadaAlta (8.8)0.83%—Jenkins Amazon EC215/1/202017/6/2026
A cross-site request forgery vulnerability in Jenkins Amazon EC2 Plugin 1.47 and earlier allows attackers to connect to an attacker-specified URL within the AWS region using attacker-specified credentials IDs obtained through another method.
ModificadaCrítica (9.8)1.6%—Amazon AWS Lambda8/1/202017/6/2026
In aws-lambda versions prior to version 1.0.5, the "config.FunctioName" is used to construct the argument used within the "exec" function without any sanitization. It is possible for a user to inject arbitrary commands to the "zipCmd" used within "config.FunctionName".
ModificadaCrítica (9.8)3.8%—Amazon Blink XT2 Sync Module Firmware31/12/201917/6/2026
Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when the device retrieves updates scripts from the internet.
ModificadaCrítica (9.8)3.7%—Amazon Blink XT2 Sync Module Firmware11/12/201917/6/2026
Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when retrieving internal network configuration data.
ModificadaAlta (8.8)1.7%—Amazon Blink XT2 Sync Module Firmware11/12/201917/6/2026
Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when configuring the devices wifi configuration via the bssid parameter.
ModificadaAlta (8.8)1.7%—Amazon Blink XT2 Sync Module Firmware11/12/201917/6/2026
Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when configuring the devices wifi configuration via the key parameter.
ModificadaAlta (8.8)1.2%—Amazon Blink XT2 Sync Module Firmware11/12/201917/6/2026
Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when configuring the devices wifi configuration via the encryption parameter.
ModificadaAlta (8.8)1.7%—Amazon Blink XT2 Sync Module Firmware11/12/201917/6/2026
Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when configuring the devices wifi configuration via the ssid parameter.
ModificadaMedia (6.8)1.0%—Amazon Blink XT2 Sync Module Firmware11/12/201917/6/2026
Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary code and commands on the device due to insufficient UART protections.
ModificadaCrítica (9.8)3.3%—Amazon Firecracker11/12/201917/6/2026
Firecracker vsock implementation buffer overflow in versions 0.18.0 and 0.19.0. This can result in potentially exploitable crashes.
ModificadaMedia (5.9)0.46%—Amazon Audible6/12/201917/6/2026
The Audible application through 2.34.0 for Android has Missing SSL Certificate Validation for Adobe SDKs, allowing MITM attackers to cause a denial of service.
ModificadaAlta (7.5)0.92%—Amazon Freertos+fat4/11/201917/6/2026
Real Time Engineers FreeRTOS+FAT 160919a has a use after free. The function FF_Close() is defined in ff_file.c. The file handler pxFile is freed by ffconfigFREE, which (by default) is a macro definition of vPortFree(), but it is reused to flush modified file content from the cache to disk by the function…
ModificadaMedia (6.1)0.92%—Awesomemotive Easy Digital DownloadsEasydigitaldownloads Amazon S323/10/201917/6/2026
The Easy Digital Downloads (EDD) Amazon S3 extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
ModificadaAlta (7.5)4.1%—S3bubble-amazon-s3-audio-streaming10/10/201917/6/2026
The s3bubble-amazon-s3-audio-streaming plugin 2.0 for WordPress has directory traversal via the adverts/assets/plugins/ultimate/content/downloader.php path parameter.
ModificadaAlta (7.5)3.7%—S3bubble-amazon-s3-html-5-video-with-adverts10/10/201917/6/2026
The s3bubble-amazon-s3-html-5-video-with-adverts plugin 0.7 for WordPress has directory traversal via the adverts/assets/plugins/ultimate/content/downloader.php path parameter.
ModificadaAlta (7.5)1.2%—Amazon WEB Services Freertos7/10/201917/6/2026
Amazon FreeRTOS up to and including v1.4.8 lacks length checking in prvProcessReceivedPublish, resulting in untargetable leakage of arbitrary memory contents on a device to an attacker. If an attacker has the authorization to send a malformed MQTT publish packet to an Amazon IoT Thing, which interacts with an…
ModificadaMedia (6.1)1.0%—Ec-cube Amazon PAY12/9/201917/6/2026
Cross-site scripting vulnerability in EC-CUBE plugin 'Amazon Pay Plugin 2.12,2.13' version 2.4.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (8.8)1.3%—Jenkins Amazon SNS Build Notifier4/4/201917/6/2026
Jenkins Amazon SNS Build Notifier Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
ModificadaAlta (7.2)1.8%—Amazon AWS Software Development KIT4/4/201917/6/2026
Amazon AWS SDK <=2.8.5 for Android uses Android SharedPreferences to store plain text AWS STS Temporary Credentials retrieved by AWS Cognito Identity Service. An attacker can use these credentials to create authenticated and/or authorized requests. Note that the attacker must have "root" privilege access to the…
ModificadaMedia (6.5)0.94%—Amazon Affiliate Store Project Amazon Affiliate Store28/3/201917/6/2026
PHP Scripts Mall Amazon Affiliate Store 2.1.6 allows Parameter Tampering of the payment amount.
ModificadaCrítica (9.1)0.59%—Amazon Ring Video Doorbell Firmware1/3/201917/6/2026
Amazon Ring Doorbell before 3.4.7 mishandles encryption, which allows attackers to obtain audio and video data, or insert spoofed video that does not correspond to the actual person at the door.
ModificadaAlta (7.4)0.69%—Amazon Fire OS17/2/201917/6/2026
Amazon Fire OS before 5.3.6.4 allows a man-in-the-middle attack against HTTP requests for "Terms of Use" and Privacy pages.
ModificadaMedia (5.9)1.8%—Amazon WEB Services FreertosAmazon Freertos6/12/201817/6/2026
An issue was discovered in Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP component. Out of bounds access to TCP source and destination port fields in xProcessReceivedTCPPacket can leak data back to an attacker.
ModificadaMedia (5.9)1.8%—Amazon WEB Services FreertosAmazon Freertos6/12/201817/6/2026
An issue was discovered in Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP component. Out of bounds memory access during parsing of DHCP responses in prvProcessDHCPReplies can be used for information disclosure.